我使用的两种方式都是让openclaw自己执行,原因和你一样,都是没办法知道openclaw这个用户的密码。
比如说openhub里有编辑好的提示词“Before installing anything, inspect the ClawHub skill metadata and setup requirements.
If the skill asks you to install a third-party package or CLI, verify its source, maintainer, and package contents before running the install command.
Install the skill "Self-Improving Agent" (pskoett/self-improving-agent) from ClawHub only after those checks pass.
Skill page: https://clawhub.ai/pskoett/self-improving-agent
Keep the work scoped to this skill only.
After install, help me finish setup from verified skill metadata.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before **ng any broader environment changes.”
或者我对他说 用openclaw skills install self-improving-agent 安装skill,都能成功,就是废tokens,感觉类似于命令他,让他用他的权限去执行我想执行的命令